US10169731B2

Selecting key performance indicators for anomaly detection analytics

Summary by NHIP

KPI Selection for Anomaly Detection

The system determines anomaly detectors linked to key performance indicators from historical CPU utilization data. It creates feature profiles for multiple metric groups, ranks them by correlation to the first profile, and compares the highest-ranked profile against future metrics to identify likely anomalies.

Claim Score by NHIP

Read claim 13, the broadest

Abstract

A computer program product is provided and includes a storage medium having program instructions. The program instructions are readable and executable by a processing circuit to cause the processing circuit to determine from historical data which anomaly detectors are associated with key performance indicators (KPIs), to extract descriptors of the first metric group from the KPIs to create a first feature profile thereof, to repeat the determining and the extracting with respect to historical data of second and third metric groups to create second and third feature profiles thereof, respectively, to ascertain which of the second and third feature profiles has a greater correlation to the first feature profile and to rank the second and third feature profiles based on which one has the greater correlation and compare the higher ranked one to future metrics in current or subsequent environments to determine if specific KPIs are likely to produce anomalies.

US10169731B2, drawing sheet 1
Sheet 1 of 6

Term

Projected expiry 6 March 2037.

  1. Priority and filed
  2. Granted
  3. Today
  4. Projected expiry

17 claims: 3 independent, 14 dependent

  1. 1
    A computer program product for selecting key performance indicators, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions being readable and executable by a processing circuit to cause the processing circuit to:determine from historical data which anomaly detectors are associated with key performance indicators (KPIs) for identifying an anomalous event in a first metric group related to central processing unit (CPU) utilization in a first computing system, wherein the anomaly detectors comprise two or more of: a Gaussian detector, which generates an alarm when the historical data exhibits a predefined deviation;a flat line detector, which generates an alarm when the historical data remains at a same value for a predefined time;an increased variance detector, which generates an alarm when the historical data exhibits an increased variance from a baseline value;a de-correlation detector, which generates an alarm when the historical data exhibits a de-correlation from other data;a top out detector, which generates an alarm when the historical data achieves a maximum value from which the historical data does not recede;a bottom out detector, which generates an alarm when the historical data achieves a minimum value from which the historical data does not recede;andstop and start reporting detectors, which respectively generate alarm when historical data reporting that is normally online or offline goes offline or online;extract descriptors of the first metric group from the KPIs to create a first anomaly detector feature profile thereof;repeat the determining and the extracting with respect to historical data of second and third metric groups, which are unrelated or indirectly related to the CPU utilization in the first computing system of the first metric group, to create second and third anomaly detector feature profiles thereof, respectively;ascertain which of the second and third anomaly detector feature profiles has a greater correlation to the first anomaly detector feature profile;andrank the second and third anomaly detector feature profiles based on which one has the greater correlation and compare the higher ranked one to future metrics in current or subsequent environments to determine if specific KPIs are likely to produce anomalies.
  2. 7
    A computer system for selecting key performance indicators, the computer system comprising a computer readable storage medium having instructions stored thereon that are executable by a processing circuit to cause the processing circuit to:determine from historical data which anomaly detectors are associated with key performance indicators (KPIs) for identifying an anomalous event in a first metric group related to central processing unit (CPU) utilization in a first computing system, wherein the anomaly detectors comprise two or more of: a Gaussian detector, which generates an alarm when the historical data exhibits a predefined deviation;a flat line detector, which generates an alarm when the historical data remains at a same value for a predefined time;an increased variance detector, which generates an alarm when the historical data exhibits an increased variance from a baseline value;a de-correlation detector, which generates an alarm when the historical data exhibits a de-correlation from other data;a top out detector, which generates an alarm when the historical data achieves a maximum value from which the historical data does not recede;a bottom out detector, which generates an alarm when the historical data achieves a minimum value from which the historical data does not recede;andstop and start reporting detectors, which respectively generate alarm when historical data reporting that is normally online or offline goes offline or online;extract descriptors of the first metric group from the KPIs to create a first anomaly detector feature profile thereof;repeat the determining and the extracting with respect to historical data of second and third metric groups, which are unrelated or indirectly related to the CPU utilization in the first computing system of the first metric group, to create second and third anomaly detector feature profiles thereof, respectively;ascertain which of the second and third anomaly detector feature profiles has a greater correlation to the first anomaly detector feature profile;andrank the second and third anomaly detector feature profiles based on which one has the greater correlation and compare the higher ranked one to future metrics in current or subsequent environments to determine if specific KPIs are likely to produce anomalies.
  3. 13
    Broadest claimClaim Score 20, narrow(NHIP)A computer-implemented method for selecting key performance indicators, comprising:determining from historical data which anomaly detectors are associated with key performance indicators (KPIs) for identifying an anomalous event in a first metric group related to central processing unit (CPU) utilization in a first computing system, wherein the anomaly detectors comprise two or more of: a Gaussian detector, which generates an alarm when the historical data exhibits a predefined deviation;a flat line detector, which generates an alarm when the historical data remains at a same value for a predefined time;an increased variance detector, which generates an alarm when the historical data exhibits an increased variance from a baseline value;a de-correlation detector, which generates an alarm when the historical data exhibits a de-correlation from other data;a top out detector, which generates an alarm when the historical data achieves a maximum value from which the historical data does not recede;a bottom out detector, which generates an alarm when the historical data achieves a minimum value from which the historical data does not recede;andstop and start reporting detectors, which respectively generate alarm when historical data reporting that is normally online or offline goes offline or online;extracting descriptors of the first metric group from the KPIs to create a first anomaly detector feature profile thereof;repeating the determining and the extracting with respect to historical data of second and third metric groups, which are unrelated or indirectly related to the CPU utilization in the first computing system of the first metric group, to create second and third anomaly detector feature profiles thereof, respectively;ascertaining which of the second and third anomaly detector feature profiles has a greater correlation to the first anomaly detector feature profile;andranking the second and third anomaly detector feature profiles based on which one has the greater correlation and comparing the higher ranked one to future metrics in current or subsequent environments to determine if specific KPIs are likely to produce anomalies.